Courseiva
Securing Traffic and App-ID →mediumMultiple Choice

PCNSE Securing Traffic and App-ID Practice Question

A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?

⚠ Common exam trap

The trap here is assuming that a port-based service object or IP-based EDL can reliably control an application that uses dynamic ports and changing IPs, but only App-ID can identify the application regardless of those factors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App-ID with application filters in the security policy

App-ID with application filters allows the firewall to identify the SaaS application by its unique traffic characteristics, not by port or IP. This ensures that only the desired application is allowed, even when it uses dynamic ports or changes IP addresses. Application filters further refine policy by grouping applications based on attributes like category and risk, providing granular control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service objects with TCP port ranges in the security policy

    Why it's wrong here

    Service objects define port ranges, but the application uses dynamic ports, so a static port range would not reliably match. Additionally, other applications could use the same ports, leading to incorrect allow. Service objects do not provide application-level visibility or control, which is required to distinguish the SaaS application from other traffic.

  • ✓

    App-ID with application filters in the security policy

    Why this is correct

    App-ID identifies the application regardless of port or IP, and application filters allow grouping applications by characteristics such as category, subcategory, technology, and risk. This enables precise control over the SaaS application while blocking others, even with dynamic ports and changing IPs. App-ID is the core technology for application-based policy enforcement on Palo Alto Networks firewalls.

  • ✗

    External Dynamic Lists (EDLs) with IP addresses of the SaaS provider

    Why it's wrong here

    EDLs are used to dynamically import IP addresses or domains for policy matching. However, the SaaS application changes server IPs frequently, making IP-based control unreliable. Moreover, EDLs do not identify the application itself, so other applications hosted on the same IPs could be inadvertently allowed, violating the requirement to block all other traffic.

  • ✗

    URL filtering profiles with custom URL categories

    Why it's wrong here

    URL filtering operates at the HTTP/HTTPS layer and classifies based on URLs, not application behavior. The SaaS application may use non-web protocols or encrypted traffic that URL filtering cannot accurately identify. This approach would not reliably control the application, especially if it uses dynamic ports and non-standard protocols.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.